Lari Lehtomäki

@latsku@infosec.exchange
39 Followers
462 Following
464 Posts

Infosec specialist 🖥, former infosec consultant & Windows sysadmin , geek 👾

"If I have seen further it is by standing on the shoulders of Giants"

#fedi22

LocationFinland
PronounsHe/him
Twitter (not active anymore)https://www.twitter.com/@larilehtomaki

iOS 26 (and OSes 26 in general) add an OS-facilitated way to securely migrate your passkeys, passwords, and other data saved in one password manager app to another. The details here are super interesting and are covered in the WWDC25 video “What's new in passkeys” (https://developer.apple.com/videos/play/wwdc2025/279). The rest of this post includes a summary of part of that video and other publicly-available information. (I am not breaking any kind of news here.)

- Data is sent from one app to the other without exporting any kind of file to a filesystem. This means it can’t accidentally be accidentally uploaded to an attacker attempting to compromise one or all of your accounts.
- There’s an OS API that password manager apps call to export their data. Then, securely and out-of-process, users select which app to send the data to. They are reminded of the scope of the data, and authentication with local biometrics or their passcode to confirm sending the data.
- The destination app is not revealed to the source app.
- Remember that crappy unstandardized CSV format for migrating passwords between password managers? It’s going to be a thing of the past, because…
- The data sendable via the API is explicitly based on the “Credential Exchange Format” (https://fidoalliance.org/specifications-credential-exchange-specifications/) standard. This standard is being developed in the FIDO Alliance, the standards body working on passkeys, but the spec covers far more than passwords and passkeys. In fact, it was co-developed by 1Password, Dashlane, and others. There’s a collection of Swift structs in the SDK implementing the standard, with as few modifications as possible.
- The data format part of the API is versioned so it can evolve as the Credential Exchange Format does.

I know it’s taken some time for this to come to fruition, but I hope that delivering a phishing-resistant credential migration process based on open standards (with a credential format standardized for the first time!) makes up for the delay. As I have said since day 1, your passkey data is yours. Passkeys are not a form of “vendor lock-in”.

What’s new in passkeys - WWDC25 - Videos - Apple Developer

Discover how iOS, iPadOS, macOS, and visionOS 26 enhance passkeys. We'll explore key updates including: the new account creation API for...

Apple Developer
It has officially begun. The CRA info request counter is no longer at zero.
The Globus is a navigational instrument that uses a rotating globe to show the position of the Soyuz spacecraft above the Earth. Inside the Globus, a complicated system of gears and motors positions the globe. Jon Bruner from @lumafield created a three-dimensional X-ray scan for us. 1/4
This is the good stuff right here. Read this whole thread on reversing a Flock camera.
https://infosec.exchange/@kajer/114702028324249657
kajer (@kajer@infosec.exchange)

Attached: 2 images Miserable piece of shit is getting opened soon.

Infosec Exchange
LLMs simulate confidence more than they do intelligence.

Why do we say 'slept like a baby'? Babies wake up every two hours crying.

I want to sleep like my cat. 14 hours, no responsibilities, zero regrets.

In the last five years, we've gone from "employees will never have to go into an office" to "employees need to be in the office because creative and innovative work can only be done face-to-face between humans" to "lol we don't need humans"

It's sunflower season starting here in Ireland at least 🌻🌻🌻. David Zinn shows how they can be cultivated on pavements using chalk, water and a large dose of whimsy ...

#DavidZinn #StreetArt #Art

Oooh. I love this article: A non-anthropomorphized view of LLMs by Halvar Flake @HalvarFlake

“I am baffled that the AI discussions seem to never move away from treating a function to generate sequences of words as something that resembles a human.”

http://addxorrol.blogspot.com/2025/07/a-non-anthropomorphized-view-of-llms.html

#AI #LLM

A non-anthropomorphized view of LLMs

In many discussions where questions of "alignment" or "AI safety" crop up, I am baffled by seriously intelligent people imbuing almost magic...

LLMs are mansplaining as a service, but more specifically that type of mansplainer who googles your question and replies authoritatively with the first result that comes up, despite having zero understanding himself.
×
@ciaranmak GPT-4o mini is still not so sure about the right answer.